First published: Thu Aug 29 2019(Updated: )
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. This issue affects: Zephyr shell versions prior to 1.14.0 on all.
Credit: vulnerabilities@zephyrproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zephyr Project Manager | <1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14202 has been assessed with a high severity due to potential arbitrary code execution.
To fix CVE-2017-14202, update to Zephyr shell version 1.14.0 or later.
CVE-2017-14202 affects all versions of Zephyr shell prior to 1.14.0.
Yes, CVE-2017-14202 can potentially allow remote code execution through improper memory buffer handling.
CVE-2017-14202 specifically affects the shell component of the Zephyr project.